<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS content filtering in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488171#M671755</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;What you see is happening is because the router cannot contact the trps.trendmicro.com to ask for the category of the sites in order to allow them or not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;You can use option&lt;SPAN class="cCN_CmdName"&gt; "server &lt;/SPAN&gt;{&lt;EM class="cArgument"&gt;server-name | ip-address&lt;/EM&gt;} [&lt;SPAN class="cKeyword"&gt;outside&lt;/SPAN&gt;] [&lt;SPAN class="cKeyword"&gt;port&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;port-number&lt;/EM&gt;] [&lt;SPAN class="cKeyword"&gt;retrans&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;retransmission-count&lt;/EM&gt;] [&lt;SPAN class="cKeyword"&gt;timeout&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;seconds&lt;/EM&gt;]" &lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;under the "parameter-map type urlfpolicy trend dynamic-parameters" to change the timeout and wait for more time until you declare the "allow-mode on". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;But that will not fix the underlying problem which is probably connectivity to t&lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;rps.trendmicro.com. Try using either of the ip addresses 216.104.8.100, 216.99.133.100 ("ip host trps.trendmicro.com 216.99.xxx" command on the router) and see what the response times are and see if you can chose the one that is the best for you and if that fixes the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 May 2010 16:31:03 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-05-05T16:31:03Z</dc:date>
    <item>
      <title>IOS content filtering</title>
      <link>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488170#M671754</link>
      <description>&lt;P&gt;This link has a good example on how to configure CISCO IOS Content Filtering &lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-8028" target="_blank"&gt;&lt;SPAN style="color: #2f6681;"&gt;http://supportforums.cisco.com/docs/DOC-8028&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i copied and pasted the config on to a 1941W router and it worked.&amp;nbsp; however, i found that the router could go in and out of the "allow mode" regularly (like every few minutes).&amp;nbsp; below is example.&amp;nbsp; during the allow mode, content filtering is basically turned off and users can hit any site.&amp;nbsp; I don't want to turn off the allow mode, but is there a way to minimize the # of times the router goes into allow mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May&amp;nbsp; 4 14:41:03.218: %URLF-3-ENTER_ALLOW_MODE: URLF classification request timed out, the router is entering allow mode.&lt;BR /&gt;May&amp;nbsp; 4 14:42:05.458: %URLF-5-LEAVE_ALLOW_MODE: Connection to an URL filter server is made, or subscription for URLF service is renewed. The router is returning from ALLOW MODE&lt;BR /&gt;May&amp;nbsp; 4 14:42:07.786: %URLF-3-ENTER_ALLOW_MODE: URLF classification request timed out, the router is entering allow mode.&lt;BR /&gt;May&amp;nbsp; 4 14:43:08.035: %URLF-5-LEAVE_ALLOW_MODE: Connection to an URL filter server is made, or subscription for URLF service is renewed. The router is returning from ALLOW MODE&lt;BR /&gt;May&amp;nbsp; 4 14:46:39.144: %URLF-3-ENTER_ALLOW_MODE: URLF classification request timed out, the router is entering allow mode.&lt;BR /&gt;May&amp;nbsp; 4 14:47:39.388: %URLF-5-LEAVE_ALLOW_MODE: Connection to an URL filter server is made, or subscription for URLF service is renewed. The router is returning from ALLOW MODE&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488170#M671754</guid>
      <dc:creator>tachyon05</dc:creator>
      <dc:date>2019-03-11T17:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: IOS content filtering</title>
      <link>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488171#M671755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;What you see is happening is because the router cannot contact the trps.trendmicro.com to ask for the category of the sites in order to allow them or not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;You can use option&lt;SPAN class="cCN_CmdName"&gt; "server &lt;/SPAN&gt;{&lt;EM class="cArgument"&gt;server-name | ip-address&lt;/EM&gt;} [&lt;SPAN class="cKeyword"&gt;outside&lt;/SPAN&gt;] [&lt;SPAN class="cKeyword"&gt;port&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;port-number&lt;/EM&gt;] [&lt;SPAN class="cKeyword"&gt;retrans&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;retransmission-count&lt;/EM&gt;] [&lt;SPAN class="cKeyword"&gt;timeout&lt;/SPAN&gt; &lt;EM class="cArgument"&gt;seconds&lt;/EM&gt;]" &lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;under the "parameter-map type urlfpolicy trend dynamic-parameters" to change the timeout and wait for more time until you declare the "allow-mode on". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;But that will not fix the underlying problem which is probably connectivity to t&lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;rps.trendmicro.com. Try using either of the ip addresses 216.104.8.100, 216.99.133.100 ("ip host trps.trendmicro.com 216.99.xxx" command on the router) and see what the response times are and see if you can chose the one that is the best for you and if that fixes the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2010 16:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488171#M671755</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-05-05T16:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: IOS content filtering</title>
      <link>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488172#M671756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i tried to not use the&lt;STRONG&gt; ip&lt;/STRONG&gt; &lt;STRONG&gt;domain lookup &lt;/STRONG&gt;on the router, and added &lt;STRONG&gt;ip host trps.trendmicro.com 216.99.133.100 216.104.8.100&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; and&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;ip host crl.geotrust.com 69.58.183.143&lt;/STRONG&gt;.&amp;nbsp; however, the router still continues to go in and out of the allow mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also tried what you said, and found out that from the router,&lt;/P&gt;&lt;P&gt;216.104.8.100's average round trip back to router is 81ms&lt;/P&gt;&lt;P&gt;216.99.133.100's average round trip back to router is 4 ms.&lt;/P&gt;&lt;P&gt;therefore, i reconfigured the &lt;STRONG&gt;ip host trps.trendmicro.com &lt;/STRONG&gt;to include only the 216.99.133.100.&amp;nbsp; thinking it will be faster, but the result is still the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any other suggestions?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 20:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-content-filtering/m-p/1488172#M671756</guid>
      <dc:creator>tachyon05</dc:creator>
      <dc:date>2010-05-06T20:57:28Z</dc:date>
    </item>
  </channel>
</rss>

